Fwd: Fwd: Re: I don't trust the NZRS DNSSEC procedures... Yet
Damn you, list software that always does the opposite of what I want.
---------- Forwarded message ----------
From: Andy Linton
Additionally, the root does not change very often and does not have any form of SLA on how quickly those changes are made, so introducing processes that create significant operational delays is not a problem for the root. Root zone changes often take days. This contrasts strongly with .nz where we have a tight SLA that requires us to publish changes within an hour and a bit of receiving them and have metrics governing how much downtime is allowed per server, how quickly changes propagate, how quickly we serve responses, etc.
I think we need to look at this more closely. .nz does not change very often - the zones that change often are co.nz, net.nz etc. So we may have different requirements for those levels. I can envisage govt.nz or mil.nz having different trust requirements from org.nz or geek.nz for example. We haven't delegated those zones in the past but it's possible that might happen. We're lumping .nz and the second level domains together and that may or may not be appropriate. I also think that we should be willing to consider changes in the performance characteristics of the system if it makes it more secure. I would certainly be willing to raise a modified SLA with the DNCL Board. Fast, reliable, cheap - pick two.
On 8/06/2011, at 2:15 PM, Andy Linton wrote:
I think we need to look at this more closely.
.nz does not change very often - the zones that change often are co.nz, net.nz etc. So we may have different requirements for those levels. I can envisage govt.nz or mil.nz having different trust requirements from org.nz or geek.nz for example. We haven't delegated those zones in the past but it's possible that might happen. We're lumping .nz and the second level domains together and that may or may not be appropriate.
Changing the .nz model for second level domains from allowing moderated domains to allowing delegated domains is a major move that would include changing just about every policy and procedure as well as significant parts of the infrastructure. I'm sure that if that were to happen there would be plenty of time to reconsider the SLA, the DPS and whatever else at that time. cheers Jay
I also think that we should be willing to consider changes in the performance characteristics of the system if it makes it more secure. I would certainly be willing to raise a modified SLA with the DNCL Board.
Fast, reliable, cheap - pick two. _______________________________________________ NZNOG mailing list NZNOG(a)list.waikato.ac.nz http://list.waikato.ac.nz/mailman/listinfo/nznog
-- Jay Daley Chief Executive .nz Registry Services (New Zealand Domain Name Registry Limited) desk: +64 4 931 6977 mobile: +64 21 678840
participants (2)
-
Andy Linton
-
Jay Daley